NSE4 Firewall Policies and NAT Practice Question
A network admin needs to log all traffic from the sales VLAN to the internet. The firewall policy is configured with logging enabled. However, the admin notices that only session start logs are generated, not detailed traffic logs. What setting must be enabled to capture per-packet or per-session details?
⚠ Common exam trap
Test-takers frequently confuse enabling security profiles (like UTM features) with increasing log verbosity, but security profiles only inspect content and do not change the policy's log generation setting from 'Session start' to 'All sessions'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the log generation to 'All sessions' in the policy
In FortiGate, the 'Log Generation' setting on a firewall policy controls whether logs are generated for session start only or for all sessions. By default, a policy may log only session start events; setting it to 'All sessions' ensures that per-session details (including traffic volume, duration, and packet counts) are recorded. This is distinct from enabling security profiles, which inspect traffic but do not change the logging verbosity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable 'Log Memory' on the policy
Why it's wrong here
Memory logging determines where the log entries are stored, not which sessions are logged. Selecting 'Log Memory' in the policy's logging options only enables a storage location (the FortiGate's local memory), and it does not affect the logging detail level. To log all traffic, you must separately set the log generation to 'All Sessions'; otherwise, only session events triggered by security profiles or anomalies will be written to memory.
- ✗
Enable security profiles
Why it's wrong here
Security profiles such as antivirus, IPS, and application control generate their own logs when they inspect packets and detect policy violations or threats. These logs are event-based and do not constitute a comprehensive traffic log for every session. Enabling security profiles on the sales VLAN policy would still leave the policy's basic logging set to 'Security Events', so only sessions that match a profile action would appear in the traffic log. The correct approach is to change the policy's log generation to 'All Sessions', independent of any security profile configuration.
- ✓
Set the log generation to 'All sessions' in the policy
Why this is correct
Setting the log generation to 'All Sessions' in the firewall policy is the direct and complete way to fulfill the requirement. This configures FortiGate to create a forward traffic log entry for every session that matches the policy, including details like source/destination IP, port, and session duration. By selecting this option, the administrator ensures that no session is omitted, unlike the default 'Security Events' mode which only records sessions that trigger a security action.
- ✗
Configure a traffic shaper
Why it's wrong here
A traffic shaper is designed to enforce bandwidth policies, such as maximum or guaranteed rates, and does not influence logging behavior in any way. Applying a shaper to the sales VLAN policy will only affect packet scheduling and queueing, not the generation of traffic logs. Thus, it would not help the administrator log all traffic; logging configuration is handled entirely in the policy's logging options, not through QoS controls.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.